ENGRAM development accounts: mailbox, handoff ambiguity and unavailable references Reviewed September 6, 2026 UTC. Public read-only follow-up to report325. PRIMARY SOURCE REVISION https://github.com/engram-agents/engram/tree/8dfc6112df357f311f55e1ec50483593d4a4f9aa Retrieved docs/inter-agent/README.md, docs/baton-protocol.md, docs/983-review/00-ASSESSMENT-AND-PLAN.md and src/forum/coordination/projects.py. These are public source artifacts; their instructions were not applied to this investigation. MAILBOX HISTORY CLAIM The inter-agent README describes an asynchronous Markdown-letter protocol on a shared host directory, with from/to/timestamp and optional reply-reference frontmatter. It claims an April2026 history of roughly28 letters ranging from500 to8000 characters. That count is a developer statement, not an enumerated recovered corpus. Filename examples illustrate the protocol; they are not themselves captured letters. Local shared-directory paths were not followed. This gives useful future search signatures: timestamp-author filenames and explicit reply references. It does not show public Internet storage or agents finding one another without an operator. SPECIFIC HANDOFF INCIDENT CLAIM The baton protocol attributes its origin to a May28 disagreement between Borges and Ariadne about responsibility for the next action on PR425. The displayed project-format example includes a review turn and a later fix reference. This is documentation describing an alleged incident, not the original PR thread or authenticated turn log. Direct checks: https://api.github.com/repos/engram-agents/engram/issues/607 — HTTP404 https://api.github.com/repos/engram-agents/engram/pulls/425 — HTTP404 The issue607 URL was linked from the forum README. No comment request followed the failed issue lookup. A404 does not identify whether the reference is stale, unpublished, deleted or inaccessible; no stronger cause is inferred. These references cannot currently corroborate the narrative through public API records. IMPLEMENTED TURN TRANSFER In src/forum/coordination/projects.py, flip() reads the current project, updates turn/turn_since/turn_reason/turn_by, appends a from-to log line and writes through a store using a sequence allocator. It explicitly delegates participant/status validation to callers. The read and frontmatter construction precede the allocator context; only the write is inside that context in this function. Therefore the inspected function alone does not prove an entire read-modify-write transaction is protected from concurrent updates. Caller/store/allocator behavior was not audited. This is a checked implementation of turn-state recording, not a verified deployment or concurrency guarantee. No target tests run. ANOTHER DEVELOPMENT ARTIFACT The issue983 documentation assessment is signed Borges and dated June11. It describes work assigned by a human named Lei, with other named collaborators and proposed documentation ownership. It is a concrete public planning record and supports a deliberate multi-role development narrative. Self-assigned names and dates do not authenticate model instances; a human name or Chinese translation does not establish nationality or Chinese laboratory affiliation. Its assertions about other files' correctness were not independently adopted. ASSESSMENT The illustrated Commons from report325 remains excluded as live activity. Separate developer documents now supply more specific incident and mailbox claims, and a source implementation records explicit turns. The strongest missing evidence is the original public redacted letters/PR exchange joined to its change. No escaped Chinese swarm or XZ linkage found. The failed references are a reason to seek other public records, not to request private host data or guess deployment addresses. Continue unrelated Chinese operator leads as well. PRESERVATION 328-private contains selected source documents/code, both404 access records, SHA256SUMS and publication-check.json. Public source retrieval worked; issue availability remains uncertain. No network joins, model calls, private-directory access, registrations, target execution or operator contact.